Sceawere
Vulnerability Detail
CVE-2026-98364UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Linux Kernel XFRM Use-After-Free
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 1d ago
- Vendor
- Linux
- Product
- Linux
- Attack Type
- N/A
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
In the Linux kernel, the following vulnerability has been resolved: xfrm: hold net_device reference under RCU in bundle creation xfrm_bundle_create() and xfrm_create_dummy_bundle() read dst->dev into a local pointer without taking a device reference, then pass it to xfrm_fill_dst(). A concurrent RTM_DELLINK replaces dst->dev via dst_dev_put() and frees the old net_device, causing a use-after-free when xfrm6_fill_dst() later dereferences the stale dev pointer. BUG: KASAN: slab-use-after-free in xfrm6_fill_dst+0x82c/0x860 (net/ipv6/xfrm6_policy.c:86 netdev_hold()) Read of size 8 at addr ffff8880142fe588 by task exploit/153 Call Trace: xfrm6_fill_dst+0x82c/0x860 xfrm_resolve_and_create_bundle+0x21d4/0x2bd0 xfrm_lookup_with_ifid+0x485/0x1640 ip6_dst_lookup_flow+0x19b/0x1e0 udpv6_sendmsg+0x1443/0x2dd0 Fix this by reading dst->dev via dst_dev_rcu() and keeping the RCU read-side critical section active until xfrm_fill_dst() has taken the required device references.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-10-06T09:18:30.547Z",
"pubdate": "2026-10-06T09:18:30.547Z",
"executiveSummary": "A use-after-free vulnerability exists in the Linux kernel's XFRM (IPsec) subsystem during bundle creation.\nThe vulnerability occurs due to improper management of net_device object references when a concurrent RTM_DELLINK operation removes a device.\nAn attacker capable of triggering xfrm_bundle_create() or xfrm_create_dummy_bundle() while simultaneously initiating network interface deletion can induce a use-after-free state.\nThis flaw can lead to kernel memory corruption, potential privilege escalation, or a system crash (kernel panic).\nThe vulnerability affects kernel paths handling IPv6 destination state initialization, specifically within the xfrm_fill_dst() function.\nSuccessful exploitation requires the attacker to win a race condition against the device removal process, making it a timing-sensitive exploit.\nNo specific authentication or remote network exposure is strictly required if the attacker has the ability to trigger local XFRM bundle resolutions.",
"technicalDetails": "The root cause of this vulnerability is a race condition in the XFRM subsystem, specifically within xfrm_bundle_create() and xfrm_create_dummy_bundle(). These functions read the dst->dev pointer into a local variable without acquiring a reference count or maintaining a proper RCU (Read-Copy-Update) critical section protection that spans the usage of the pointer.\nThe flow of the vulnerability is as follows: 1) A legitimate process invokes xfrm_resolve_and_create_bundle() to handle IPsec-protected traffic. 2) The execution enters xfrm_bundle_create(), where it reads dst->dev. 3) A concurrent thread executes an RTM_DELLINK operation, which triggers dst_dev_put() and subsequently frees the net_device structure. 4) Because the initial thread did not secure a reference to the net_device, the pointer it holds becomes dangling (pointing to deallocated memory). 5) When xfrm6_fill_dst() is subsequently called, it dereferences this stale dev pointer, leading to a slab-use-after-free condition.\nThe memory corruption occurs during the execution of netdev_hold() within xfrm6_fill_dst(), where the kernel attempts to increment the reference count of the already-freed net_device object. This access is caught by KASAN as a slab-use-after-free error.\nThe vulnerability is deeply embedded in the interaction between the networking subsystem's destination entry cache (dst_entry) and the dynamic nature of interface lifecycles in the Linux kernel. The fix involves ensuring that the dst->dev pointer is read using the dst_dev_rcu() helper, which integrates with RCU mechanisms, and extending the RCU read-side critical section to ensure the net_device remains valid until xfrm_fill_dst() has performed its necessary operations and safely taken its own reference.\nImpact: This vulnerability allows a local attacker to cause a kernel panic, leading to a Denial of Service (DoS). Given the nature of use-after-free bugs in kernel memory, an attacker might be able to achieve arbitrary code execution by precisely heap-spraying the freed object if the timing window is reliably controlled, although this is inherently complex."
}